← All guides

WordPress: use Antispam Bee with data minimisation

Antispam Bee is an alternative to external comment spam services: the plugin works without CAPTCHA and, according to current project documentation, does not send any personal comment data to a third-party service.

Requirements

WordPress administration access and a backup of current plugin settings.

IP still remains an issue

Some checking methods can use the visitor IP. For example, current documentation indicates that country checking behind a proxy requires a correct client IP. For “We don’t save!” Therefore, only activate the checks that are really needed.

Remove WordPress comment IP separately

Antispam Bee does not replace the data protection configuration of the WordPress comment system itself. In particular, it must be checked separately whether WordPress or other plugins store the comment IP.

Avoid external functions

Evaluate options that involve external services or Gravatar queries separately. A spam filter that works locally is only completely local if the selected additional functions do not contact third parties again.

Test

Create test comments and check plugin settings, comment IP and external requests.

Dismantling

If there are problems, restore the backed up plugin settings and check again.

Basis

Before an external challenge service, first the local options from CAPTCHA and spam protection: first local, then external check. Only use external services if honeypot, time check, server-side validation and rate limits are not sufficient.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑